tiktok-ad-research

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill connects to api.crawlora.net, which is the official API endpoint for the vendor crawlora-org.\n- [COMMAND_EXECUTION]: The included scripts/crawlora.sh script handles API requests. It implements security controls such as strict path whitelisting and input sanitization to prevent unauthorized route access or shell injection.\n- [DATA_EXFILTRATION]: The helper script prevents local file disclosure (LFD) by rejecting the @ symbol in query parameters and using data-binary via stdin for POST requests, preventing curl from reading local system files.\n- [SAFE]: API keys are managed via environment variables and passed to curl through temporary files with restricted permissions (chmod 600), ensuring credentials do not appear in cleartext in command-line process lists.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:43 AM
Security Audit — agent-trust-hub — tiktok-ad-research